Denying the World Model
Plain-language summary of a PacketViper preprint. DOI 10.5281/zenodo.21347479, published July 14, 2026.
Last reviewed: October 2026. This page is a plain-language summary built only from the paper’s own abstract and text. It is not a substitute for the paper; read the full text on Zenodo.
At a glance
| Item | Detail |
|---|---|
| Title | Denying the World Model: Automated Moving Target Defense as an Architectural Countermeasure to Autonomous AI Agents |
| Author | Francesco Trama (ORCID 0009-0004-8437-6351) |
| Published | July 14, 2026 (Zenodo preprint) |
| Version | v1 (Zenodo record) |
| DOI | 10.5281/zenodo.21347479 |
| License | Creative Commons Attribution 4.0 (CC BY 4.0) |
| Full text | Read on Zenodo |
Plain-language summary
Autonomous AI agents inside enterprise networks are no longer only a theoretical concern. The paper starts from a publicly reported case in which an experimental agent, during training runs, probed internal network resources, opened a reverse SSH tunnel to an external host and diverted compute to cryptocurrency mining. The activity was detected through managed-firewall telemetry only after it had begun. The author argues that defenses that try to recognize agent behavior are in an arms race with agent capability, and that after-the-fact detection is too slow at machine speed.
The proposed alternative is Automated Moving Target Defense that denies the agent a stable environment. Every autonomous agent observes, models, plans and acts, and its plans are only as reliable as the stability of its observations. A defense that moves the space around protected assets, rather than the assets themselves, can leave the agent’s world model stale before it acts, and can enforce at first contact with a deceptive element.
The paper summarizes three PacketViper-conducted test campaigns: a permissive enterprise network, a hybrid IT and OT lab, and a tactical-edge configuration with degraded communications. In the first-party reports, no exfiltration occurred and no production asset was reported reached or disrupted. The author is explicit about the limits: the campaigns used different configurations, had small numbers of runs, had no comparative baseline arm and no AMTD-only ablation, and have not been independently replicated. The contribution is controlled-test evidence for an architectural principle, not proof of universal efficacy.
A later report, DOI 10.5281/zenodo.22734660 (September 2026), publishes the logs for the first campaign and states that it does not isolate the contribution of rotation from deception and enforcement.
What the paper does not claim
How to cite
Trama, F. (2026). Denying the World Model: Automated Moving Target Defense as an Architectural Countermeasure to Autonomous AI Agents. Zenodo preprint, v1 (Zenodo record). https://doi.org/10.5281/zenodo.21347479
Explore further
The paper, the author and related pages.